CVE-2026-92370

Published Sep 29, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-92370 is an improper access control vulnerability affecting TeamViewer Full Client, Host, and related modules on Windows, Linux, and macOS platforms prior to version 15.82. The flaw occurs during the session establishment phase, where the software fails to properly validate access rights against configured security policies. This allows an authenticated remote attacker to manipulate or bypass user-configured permission settings by modifying access control parameters for restricted features. By exploiting this vulnerability, an attacker can perform actions that were explicitly denied by the victim's configuration. This bypass can lead to unauthorized actions on the target system, potentially allowing the attacker to achieve remote code execution. TeamViewer has addressed this issue in version 15.82, as well as in supported maintenance and legacy releases, and recommends that users update their software to resolve the issue.

Description
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Source
psirt@teamviewer.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@teamviewer.com
CWE-284

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

  1. TeamViewer、複数の深刻な脆弱性への「早急な」パッチ適用を呼びかけ(CVE-2026-92370、CVE-2026-19743他) | Codebook|Security News https://t.co/N8SIMLUaID

    @ohhara_shiojiri

    2 Oct 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨TeamViewer、複数の深刻な脆弱性への「早急な」パッチ適用を呼びかけ(CVE-2026-92370、CVE-2026-19743他) ⚠️シスコ、SD-WAN Managerにおける認証バイパスの脆弱性を悪用した攻撃について警告(CVE-2026-76504) 〜サ

    @MachinaRecord

    1 Oct 2026

    191 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  3. CVE-2026-92370 (CVSS 8.8) en TeamViewer Full Client/Host: improper access control — un atacante autenticado remoto salta permisos de sesión y llega a RCE. Advisory TV-2026-1010 (29 sep); vendor urgió actualizar "as soon as possible". También High: path traversal CVE-2026-19

    @jfernandogg

    30 Sept 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371 Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services https://t.co/dHKdKzjvlU

    @autumn_good_35

    30 Sept 2026

    368 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Update to 15.82 now. Five high-severity TeamViewer vulnerabilities include CVE-2026-92370, CVE-2026-19743 and CVE-2026-92368 in Full Client and Host. #TeamViewer #RemoteAccess #CVE202692370 #PrivilegeEscalation #Windows #Linux #macOS #PatchNow https://t.co/3mmFZXyga0

    @Daily_CyberSec

    30 Sept 2026

    404 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes